All certifications / A+ Core 2 / Cheat sheet
A+ Core 2 220-1202 cheat sheet
Domain 1: Operating systems (28%)
Exam tips
- End-of-life does not mean the OS stops working; it means no more security patches. Answers about EOL systems point to upgrading or replacing them, or isolating them if they cannot be replaced.
- 'File too large' on a drive with plenty of free space almost always means FAT32 and its 4 GB per-file limit. Reformat as exFAT for Windows and Mac sharing, or NTFS for Windows only.
- Match keywords: keep files and apps means in-place upgrade or repair install; start fresh means clean install; many identical machines means image deployment; network boot means PXE; disks over 2 TB need GPT.
- If a question mentions domain join, gpedit.msc, BitLocker or accepting Remote Desktop connections on a Home machine, the answer is an edition upgrade to Pro or higher, not a reinstall.
- Task Manager shows real-time use while Performance Monitor records data over time. lusrmgr.msc and gpedit.msc are not available on Windows Home, and Event Viewer is the tool for what already happened.
- Know the pairs: sfc repairs system files and DISM repairs the image sfc uses; gpupdate applies policy and gpresult reports it; tracert shows the path and pathping adds per-hop loss statistics.
- If a driver fix or update does not seem to take effect after Shut down, remember fast startup: choose Restart instead. Sleep keeps data in RAM and uses power; hibernate saves to disk and uses none.
- A 169.254.x.x address means DHCP failed, not that the network is fine. The Public profile blocks discovery and sharing; Private allows it on trusted networks.
- Map Mac tools to Windows equivalents: Activity Monitor is Task Manager, Force Quit is End task, FileVault is BitLocker, Time Machine is backup, Disk Utility is Disk Management plus chkdsk, Spotlight is search.
- Octal permissions come up often: 7 = rwx, 6 = rw-, 5 = r-x, 4 = r--. Also remember that /etc/passwd holds accounts but /etc/shadow holds the password hashes.
- A 64-bit OS runs 32-bit apps, but a 32-bit OS cannot run 64-bit apps. If an installer refuses to run on an older machine, check whether the OS is 32-bit before blaming the software.
- Cloud sync replicates deletions and ransomware-encrypted files too, so it is not a backup. If a user has no mailbox or cannot activate office apps, check licence assignment first.
Key terms
- Operating system (OS)
- The software that manages hardware resources and provides services to applications and users.
- Distribution (distro)
- A packaged version of Linux that combines the Linux kernel with tools, a package manager and default software.
- ChromeOS
- Google's lightweight, browser-centred operating system for Chromebooks that updates itself automatically.
- Over-the-air (OTA) update
- An operating system update delivered wirelessly to a mobile device.
- Life cycle
- The vendor's published timeline of support phases for a product, from release to retirement.
- End-of-life (EOL)
- The point after which a vendor stops providing patches and support for a product.
- Extended support
- A later support phase, sometimes paid, in which only security fixes are provided.
- File system
- The structure an operating system uses to name, store, locate and protect files on a volume.
- NTFS
- The Windows default file system, with permissions, EFS encryption, compression, quotas and journaling.
- ReFS
- Microsoft's Resilient File System, which uses checksums and self-repair for large, integrity-focused storage.
- FAT32
- A widely compatible legacy file system with a 4 GB maximum file size and no permissions.
- exFAT
- A flash-oriented file system without FAT32's 4 GB file limit, readable and writable by Windows and macOS.
- ext4 and XFS
- Journaled Linux file systems; ext4 is a common default and XFS is the Red Hat default for high performance.
- APFS
- Apple File System, the SSD-optimized default for macOS, iOS and iPadOS with snapshots and encryption.
- Journaling
- Recording pending changes in a log so a file system can recover consistently after a crash.
- ISO file
- A single-file image of an optical disc that can be mounted, burned or written to USB.
- PXE
- Preboot Execution Environment, which lets a network card boot a computer from a deployment server.
- Clean install
- Installing a fresh OS on a wiped partition, removing previous apps, settings and data.
- In-place upgrade
- Installing a newer OS version over the existing one while keeping files, settings and most apps.
- Image deployment
- Copying a standardized, pre-built OS image to many computers.
- Repair install
- Reinstalling the same OS version over itself to fix system files while keeping data and apps.
- MBR
- Legacy partition style limited to about 2 TB disks and four primary partitions.
- GPT
- Modern partition style used with UEFI that supports very large disks and many partitions.
- Windows Home
- The consumer edition, without domain join, Group Policy Editor, BitLocker management or Remote Desktop host.
- Windows Pro
- The business edition that adds domain join, Group Policy, BitLocker, Remote Desktop host and Hyper-V.
- Windows Enterprise
- The volume-licensed edition for organizations with Pro features plus advanced security and management.
- Windows Education
- Enterprise-level features licensed for schools and universities.
- Domain join
- Adding a computer to a directory such as Active Directory so it uses central accounts and policies.
- Remote Desktop host
- A computer that accepts incoming Remote Desktop connections, available in Pro and higher.
- TPM 2.0
- A hardware security chip that stores keys, required by Windows 11 and used by BitLocker.
- Task Manager
- Real-time view of processes, performance, startup apps, services and users, opened with Ctrl+Shift+Esc.
- Microsoft Management Console (MMC)
- A framework that hosts administrative snap-ins such as Event Viewer and Device Manager.
- Event Viewer
- The snap-in that displays Application, Security and System logs for troubleshooting past events.
- Performance Monitor
- A tool that logs performance counters over time to build baselines and find trends.
- Resource Monitor
- A detailed view of which processes are using specific files, disk, network and memory resources.
- System Configuration (msconfig)
- A tool for changing boot options such as Safe Mode and disabling services for clean-boot troubleshooting.
- Registry
- The hierarchical database of Windows and application settings, edited with regedit.
- robocopy
- Robust File Copy, a resilient copy tool that retries, resumes, preserves permissions and can mirror folders.
- diskpart
- An interactive command-line tool for managing disks, partitions and volumes with no undo.
- chkdsk
- Checks a volume for file system errors; /f fixes errors and /r also finds bad sectors.
- sfc
- System File Checker, which scans and repairs protected Windows system files.
- DISM
- Deployment Image Servicing and Management, which repairs the Windows component store that sfc relies on.
- gpupdate and gpresult
- gpupdate applies Group Policy now; gpresult reports which policies were applied.
- nslookup
- A tool that queries DNS servers to test name resolution.
- pathping
- Combines ping and tracert to measure latency and packet loss at each hop over time.
- Settings app
- The modern Windows configuration interface, opened with Windows key + I.
- Control Panel
- The classic Windows configuration interface containing applets such as Programs and Features and Power Options.
- Sleep
- A low-power state that keeps the session in RAM for very fast resume but still uses power.
- Hibernate
- Saves RAM contents to hiberfil.sys on disk and powers off fully, resuming more slowly with no power used.
- Fast startup
- A shutdown mode that hibernates the kernel session to speed the next boot; Restart bypasses it.
- Default apps
- Settings that decide which application opens each file type or link type.
- Active hours
- The period when Windows Update avoids automatically restarting the device.
- Workgroup
- A peer-to-peer arrangement where each Windows computer keeps its own local accounts.
- Domain
- A centrally managed network where a domain controller provides accounts, authentication and Group Policy.
- UNC path
- A network path in the form \\server\share used to reach shared resources.
- Mapped drive
- A drive letter assigned to a network share so it appears like a local drive.
- APIPA
- Automatic Private IP Addressing, which assigns a 169.254.x.x address when no DHCP server responds.
- Network profile
- The Public, Private or Domain category that sets discovery, sharing and firewall behaviour for a connection.
- Proxy server
- A server that forwards web requests on a client's behalf for filtering, logging or caching.
- Metered connection
- A setting that tells Windows data is limited or costly so it reduces background downloads.
- .dmg
- A macOS disk image file that mounts like a drive and usually contains an app to drag into Applications.
- .pkg
- A macOS installer package that runs a wizard and can install components in several system locations.
- Time Machine
- The built-in macOS backup tool that keeps hourly, daily and weekly versions on an external or network drive.
- FileVault
- macOS full-disk encryption, protected by the user's password and a recovery key.
- Keychain
- The macOS password manager that stores passwords, certificates and secure notes.
- Spotlight
- The macOS system-wide search, opened with Command + Space.
- Disk Utility
- The macOS tool for erasing, formatting, partitioning and repairing drives with First Aid.
- Force Quit
- Ends an unresponsive macOS app, opened with Command + Option + Esc.
- chmod
- Changes file permissions using symbolic notation or octal numbers such as 750.
- chown
- Changes the owner and group of a file or directory.
- sudo
- Runs a single command with elevated privileges using the user's own password, with logging.
- su
- Switches to another user account, root by default, using that account's password.
- Package manager
- A tool such as apt or dnf that installs and updates software from repositories and resolves dependencies.
- /etc/shadow
- The root-only file that stores hashed passwords and password-aging information.
- /etc/fstab
- The file listing file systems to mount automatically at boot.
- /etc/resolv.conf
- The file listing the DNS servers a Linux system uses.
- 32-bit (x86)
- An architecture whose applications can address about 4 GB of memory; runs on 32-bit and most 64-bit systems.
- 64-bit (x64)
- An architecture that can address far more memory and requires a 64-bit operating system.
- System requirements
- The vendor's minimum and recommended OS, CPU, RAM, GPU and storage needed to run software.
- VRAM
- Video RAM on a graphics card, required in minimum amounts by graphics-heavy applications.
- Hash verification
- Comparing a downloaded file's hash with the vendor's published value to confirm it is unaltered.
- Business impact
- The effect of an installation on devices, the network, operations and licensing or compliance.
- Cloud productivity suite
- A subscription service providing hosted email, storage, office apps and collaboration tools.
- IMAP
- Internet Message Access Protocol, which keeps mail on the server and syncs folders across devices.
- POP3
- Post Office Protocol version 3, which downloads mail to a single device and usually removes it from the server.
- SMTP
- Simple Mail Transfer Protocol, used to send email.
- Synced storage
- A cloud service that keeps files synchronized across a user's devices, such as OneDrive or Google Drive.
- Files-on-demand
- A sync feature that lists all files but downloads content only when the file is opened.
- Licence assignment
- Allocating a subscription plan to a user so they receive the included apps and services.
- Deprovisioning
- Disabling a departing user's access, handling their data per policy and reclaiming their licence.
Domain 2: Security (28%)
Exam tips
- Bollards stop vehicles, not people. Access control vestibules stop tailgating. Video surveillance mainly detects and records rather than prevents, although visible cameras also deter.
- A password plus a PIN is still single-factor, because both are something you know. Of the listed MFA methods, SMS and email codes are the weakest and hardware tokens the strongest.
- For combined share and NTFS permissions, take the most restrictive. Copying a file inherits the destination's permissions; moving within the same volume keeps the original permissions.
- RADIUS uses UDP, encrypts only the password and is common for Wi-Fi and VPN users. TACACS+ uses TCP, encrypts everything and is common for admin access to network devices. Always choose AES over TKIP and WPA3 over WPA2 when available.
- Match the symptom: encrypted files with a ransom note mean ransomware; unexplained high CPU means a cryptominer; malware loading before the OS means a boot sector virus or rootkit, which calls for scanning from recovery or bootable media.
- Know the channels: phishing is email, vishing is voice, smishing is SMS, QR code phishing is a scanned code and whaling targets executives. An evil twin is a fake Wi-Fi network; an on-path attack is interception between two parties.
- Most questions ask for the next step. Quarantine comes before disabling System Restore; updating the anti-malware software comes before scanning; re-enabling System Restore comes after the system is clean; educating the user is last.
- Lost or stolen laptop questions point to data-at-rest encryption. 'Users leave desks unattended' points to screen lock timeouts. 'Malware spreads from USB sticks' points to disabling AutoRun and AutoPlay.
- For BYOD, the answer is usually a work profile plus a selective wipe of corporate data, not a full wipe of the employee's personal phone. Remote wipe only works if it was set up before the device was lost.
- Degaussing does nothing to SSDs or flash media, and a quick or standard format does not remove data. If the drive must be reused, wipe it; if it must never be readable again, physically destroy it and get a certificate.
- The first hardening step for any SOHO router is changing the default admin password. Port forwarding needs a stable internal address, so pair it with a DHCP reservation or static IP. Ports opening by themselves means UPnP; a guessable setup PIN means WPS.
- Private browsing only avoids saving history, cookies and form data on the local device; it is not anonymity or malware protection. A valid padlock proves encryption to a named domain, not that the site is trustworthy.
Key terms
- Defense in depth
- Using several layers of security controls so that one failure does not expose everything.
- Access control vestibule
- A two-door entry space that allows only one door open at a time, preventing tailgating.
- Badge reader
- A device that reads an ID card or fob, unlocks for authorized users and logs entries.
- Bollard
- A short, sturdy post that blocks vehicles while allowing pedestrians to pass.
- Video surveillance
- Cameras that deter, monitor and record activity for evidence.
- Alarm system
- Sensors such as door contacts, glass-break and motion detectors that alert when triggered.
- Tailgating
- Following an authorized person through a secured entrance without authenticating.
- Least privilege
- Granting users and services only the minimum access required for their tasks.
- Zero trust
- A model where no user or device is trusted by default and every access request is verified.
- Multifactor authentication (MFA)
- Authentication using two or more different factor types: know, have and are.
- Single sign-on (SSO)
- Authenticating once to an identity provider to access many applications.
- Directory service
- A central database of users, groups and computers, such as Active Directory, used for authentication.
- Access control list (ACL)
- A list of permissions or rules stating who or what traffic is allowed or denied.
- Mobile device management (MDM)
- Central enrolment and control of devices to enforce policy and remotely lock or wipe them.
- Data loss prevention (DLP)
- Tools that detect and block sensitive data from leaving the organization improperly.
- Microsoft Defender Antivirus
- Built-in Windows anti-malware with real-time, cloud-delivered and scheduled scanning.
- User Account Control (UAC)
- A feature that runs users with standard rights and prompts before elevating for system changes.
- Share permissions
- Full Control, Change and Read permissions that apply only to network access to a shared folder.
- NTFS permissions
- File and folder permissions that apply both locally and over the network.
- Inheritance
- Child files and folders automatically receiving the permissions of their parent folder.
- BitLocker
- Full-volume encryption for Windows, usually protected by the TPM and a recovery key.
- EFS
- Encrypting File System, which encrypts individual NTFS files tied to a user's certificate.
- Windows Hello
- Device-bound sign-in using a PIN, fingerprint or facial recognition.
- WPA2
- Wi-Fi security standard using AES-CCMP, in Personal (pre-shared key) or Enterprise (802.1X) modes.
- WPA3
- The current Wi-Fi security standard, using SAE in Personal mode and requiring Protected Management Frames.
- AES
- Advanced Encryption Standard, the strong cipher used by WPA2 and WPA3.
- TKIP
- Temporal Key Integrity Protocol, a deprecated cipher from the original WPA.
- RADIUS
- An open AAA protocol over UDP, commonly used for Wi-Fi, VPN and network access authentication.
- TACACS+
- A Cisco-originated AAA protocol over TCP that encrypts the whole payload, used for device administration.
- Kerberos
- The ticket-based authentication protocol used in Active Directory domains for single sign-on.
- 802.1X
- Port-based network access control that passes authentication to a server such as RADIUS.
- Virus
- Malware that attaches to a host file or program and spreads when that host is run or shared.
- Trojan
- Malware disguised as legitimate software that carries a hidden malicious function.
- Rootkit
- Malware that hides deep in the OS or firmware to conceal itself and keep privileged access.
- Ransomware
- Malware that encrypts or steals data and demands payment.
- Fileless malware
- Malware that runs in memory and abuses built-in tools instead of installing executable files.
- Cryptominer
- Malware that uses a victim's CPU or GPU to mine cryptocurrency.
- EDR
- Endpoint detection and response, which records endpoint activity, detects threats and can isolate devices.
- Email security gateway
- A filter that blocks spam, phishing and malicious attachments before they reach mailboxes.
- Phishing
- Fraudulent messages impersonating trusted senders to steal credentials or deliver malware.
- Whaling
- Phishing aimed at senior executives.
- Vishing and smishing
- Social engineering by voice call and by SMS text message respectively.
- Business email compromise (BEC)
- Using a compromised or spoofed business email account to trick staff into payments or data release.
- Evil twin
- A rogue access point imitating a legitimate Wi-Fi network to intercept traffic.
- On-path attack
- An attacker positioned between two parties to intercept or alter communication.
- Zero-day
- A vulnerability with no available patch because the vendor has had no time to fix it.
- Supply chain attack
- Compromising a trusted supplier or its products to reach that supplier's customers.
- Investigate and verify
- Step 1: confirm symptoms are caused by malware before taking action.
- Quarantine
- Step 2: isolate the infected system from networks and shared media to stop spread.
- System Restore
- A Windows feature that saves restore points, which can harbour malware and so is disabled during cleanup.
- Remediation
- Step 4: update anti-malware, then scan and remove using Safe Mode or a preinstallation environment, or reimage.
- Preinstallation environment
- A minimal boot environment such as Windows PE used to scan while the infected OS is not running.
- Restore point
- A snapshot of system files and settings that Windows can roll back to.
- End-user education
- Step 7: teaching the user how the infection happened and how to avoid it.
- Hardening
- Reducing a system's attack surface by removing, disabling and securing features.
- Data-at-rest encryption
- Encrypting stored data, for example with BitLocker or FileVault, so a stolen drive is unreadable.
- Password policy
- Rules for password length, complexity, history, expiration and lockout, often enforced by Group Policy.
- Account lockout
- Temporarily disabling an account after a set number of failed sign-in attempts.
- Screen lock timeout
- Automatically locking the session after a period of inactivity, requiring a password to resume.
- AutoRun and AutoPlay
- Features that launch or prompt actions when media is inserted; hardening disables them.
- Guest account
- A built-in account allowing access without personal credentials, which should remain disabled.
- Screen lock
- A PIN, passcode, pattern or biometric required to unlock a mobile device.
- Remote wipe
- Erasing a device's data remotely, which must be configured before loss.
- Locator app
- A service that shows a lost device's location and can lock it or play a sound.
- Device encryption
- Encryption of mobile storage tied to the screen lock to protect data at rest.
- BYOD
- Bring your own device, where employees use personal devices for work, usually with a separate work profile.
- Selective wipe
- Removing only corporate apps and data from a device while leaving personal data intact.
- COPE
- Corporate-owned, personally enabled devices that the company owns but allows some personal use.
- Shredding
- Mechanically cutting media into small pieces so it cannot be read or reassembled.
- Degaussing
- Using a strong magnetic field to erase magnetic media; ineffective on SSDs, flash and optical discs.
- Drilling
- Boring holes through drive platters to make a drive unusable, less thorough than shredding.
- Incineration
- Burning media completely, often for paper and highly sensitive material.
- Wiping
- Overwriting all addressable storage so previous data cannot be recovered, allowing reuse.
- Standard format
- Creating a new empty file system without removing old data, which remains recoverable.
- Secure erase
- A drive's built-in command, important for SSDs, that sanitizes all cells including those hidden by wear leveling.
- Certificate of destruction
- A vendor's document recording which devices were destroyed, how and when.
- SOHO router
- An all-in-one device combining routing, switching, wireless access, firewall and DHCP for a small office or home.
- WPS (Wi-Fi Protected Setup)
- A convenience feature for joining Wi-Fi by button or PIN whose PIN method can be guessed quickly, so it should be disabled.
- UPnP (Universal Plug and Play)
- A feature that lets devices open router ports automatically without approval, which malware can abuse.
- Port forwarding
- A rule that sends traffic arriving on an external port to a specific internal IP address and port.
- DHCP reservation
- A setting that always gives the same IP address to a device identified by its MAC address.
- Content filtering
- Blocking websites by category or domain at the router or another filtering device.
- Guest network
- A separate SSID and network segment that gives visitors internet access without reaching internal resources.
- Screened subnet
- A separate network zone, formerly called a DMZ, for devices that must be reachable from the internet.
- Hash check
- Comparing a computed hash of a downloaded file with the vendor's published value to confirm the file was not altered.
- Browser extension
- An add-on that extends browser features and may be able to read and change the pages you visit.
- Password manager
- A tool that generates, stores and auto-fills unique strong passwords and will not fill them on look-alike domains.
- Certificate authority (CA)
- A trusted organization that issues digital certificates binding a public key to a domain name.
- Pop-up blocker
- A browser feature that stops sites from opening unwanted new windows, with exceptions for trusted sites.
- Private browsing
- A mode that does not keep history, cookies or form data after the window closes, without hiding activity from networks or sites.
- Profile sync
- Signing the browser into an account so bookmarks, passwords, extensions and settings follow the user across devices.
Domain 3: Software troubleshooting (23%)
Exam tips
- Unexpected shutdowns without a BSOD usually mean heat or power. 'No OS found' often means boot order or a USB drive left attached. A clock that resets after power loss means the CMOS battery, and domain sign-in failures with a wrong clock mean time drift.
- Pick the least invasive fix that matches the cause: restart before reinstall, update or repair the app before repairing Windows, sfc then DISM then sfc, System Restore before reimage. If only one user has the problem, suspect the profile.
- Use the right tool for the question: 'what is slow right now' is Task Manager, 'what errors were logged' is Event Viewer, 'what changed before this started' is Reliability Monitor, and 'Windows will not boot' is WinRE.
- Screen will not rotate: check rotation lock first. App will not update: check storage and OS compatibility. Bluetooth accessory will not connect: unpair and re-pair. Factory reset is always the last step, after a backup.
- Jailbreaking, rooting, unofficial stores and sideloading are causes; high data use, battery drain, fake warnings and strange app behavior are symptoms. The usual remedy for a compromised or jailbroken device is backing up personal data and a factory reset.
- When security software and Windows Update both fail, or only security sites are unreachable, suspect malware. Real Windows security alerts come from Windows Security or the managed antivirus, never from a browser pop-up with a phone number.
- Certificate errors on every site usually mean a wrong system clock, or an intercepting proxy or rogue root certificate. A warning on just one site usually means that site's certificate has a problem, or that connection is being intercepted.
- If malware keeps coming back after removal, look for persistence: Startup apps, Run keys, services and especially scheduled tasks. If web traffic still misbehaves, check the proxy, DNS and hosts file.
Key terms
- BSOD (stop error)
- A Windows fatal error screen that halts the system and shows a stop code, often caused by drivers, RAM or heat.
- Stop code
- The identifier on a blue screen that names the kind of fatal error and helps locate the cause.
- Memory leak
- A program fault where memory is allocated but never released, gradually exhausting RAM.
- No OS found
- A boot error meaning firmware could not find a bootable operating system on the devices in the boot order.
- USB controller resource warning
- A message that a USB controller has run out of endpoints or bandwidth because too many devices share it.
- Time drift
- A system clock that is wrong or gradually wanders, which can break Kerberos authentication and certificate checks.
- CMOS battery
- The small motherboard battery that keeps firmware settings and the real-time clock while the PC is unplugged.
- sfc /scannow
- The System File Checker command that scans and repairs protected Windows system files from the component store.
- DISM
- Deployment Image Servicing and Management, used with /RestoreHealth to repair the component store that sfc depends on.
- System Restore
- A feature that returns system files, drivers, registry and programs to an earlier restore point without changing personal files.
- In-place repair install
- Running Windows setup over the existing installation to replace system files while keeping apps and data.
- Reimage
- Wiping a computer and reinstalling a standard operating system image, the most thorough and disruptive fix.
- Rebuilding a user profile
- Replacing a corrupt Windows user profile with a fresh one and copying the user's data back.
- Roll back
- Reverting a driver or update to the previous version when the new one causes problems.
- Event Viewer
- The Windows log reader showing Application, System, Security and other logs with levels, sources and Event IDs.
- Event ID
- A number that identifies a specific type of logged event and can be looked up in documentation.
- Reliability Monitor
- A timeline of failures, warnings and installs used to find what changed before a problem began.
- Task Manager
- A tool showing current processes, performance, startup apps and services.
- Resource Monitor
- A detailed view of per-process CPU, memory, disk and network activity, opened from Task Manager.
- Safe Mode
- A startup mode that loads only essential drivers and services to isolate third-party causes.
- Windows Recovery Environment (WinRE)
- A recovery OS offering Startup Repair, Safe Mode access, System Restore, uninstalling updates and a command prompt.
- Force stop
- Ending an app's process completely so it can be relaunched from a clean state.
- Clear cache
- Removing an app's temporary files without deleting the user's account or settings.
- Clear data
- Resetting an app to its freshly installed state, removing its settings and sign-in.
- Offload app
- An iOS option that removes an app but keeps its documents and data for reinstallation.
- Reset network settings
- Clearing saved Wi-Fi networks, Bluetooth pairings and VPN settings to fix stubborn connectivity problems.
- NFC (near-field communication)
- Very short-range wireless used for contactless payments and tap-to-pair.
- Rotation lock
- A setting that keeps the screen in portrait orientation regardless of how the device is held.
- Accelerometer
- A sensor that detects movement and orientation, used for autorotation.
- Sideloading
- Installing an app from outside the official app store, bypassing its security screening.
- APK (Android Package)
- The file format used to distribute and install Android apps.
- Jailbreaking
- Removing Apple's iOS restrictions to gain full control, which weakens the security model.
- Rooting
- Gaining full administrative (root) access on Android, which removes built-in protections.
- Unofficial app store
- A third-party marketplace that does not screen apps as thoroughly as official stores.
- Scareware
- Fake security warnings designed to frighten users into installing malware, paying or calling a scammer.
- Stalkerware
- Hidden monitoring software installed to track a person's location, messages or activity without consent.
- Rogue antivirus
- Fake security software that reports invented infections to extort payment or install malware.
- Hosts file
- A local file that maps names to IP addresses before DNS is used, which malware can edit to redirect or block sites.
- Rogue proxy
- An unauthorized proxy setting that routes the PC's web traffic through a server controlled by an attacker.
- System File Checker (sfc)
- A Windows tool that scans protected system files and repairs altered or missing ones.
- Quarantine
- Isolating an infected system from the network so malware cannot spread or communicate.
- Malware removal procedure
- CompTIA's seven ordered steps from verifying symptoms through educating the user.
- Adware
- Unwanted software that displays advertising, often through pop-ups, injected ads or redirected searches.
- Browser hijacker
- Software or an extension that changes the home page, search engine or new tab page without consent.
- Certificate warning
- A browser message that a site's certificate is expired, mismatched or from an untrusted issuer.
- On-path attack
- An attack where someone intercepts traffic between two parties, formerly called man-in-the-middle.
- Rogue root certificate
- An unauthorized certificate authority certificate installed so that intercepted traffic appears trusted.
- Cryptomining script
- Code that uses the visitor's CPU to mine cryptocurrency, slowing the browser.
- Tech support scam
- A fake alert urging the user to call a number or allow remote access to fix a non-existent problem.
- Persistence
- A mechanism that lets malware survive reboots or removal attempts, such as a scheduled task or startup entry.
- Run key
- A registry location whose entries launch programs automatically when a user signs in.
- Startup folder
- A folder, opened with shell:startup, whose shortcuts run at sign-in.
- Task Scheduler
- The Windows tool that runs programs on triggers such as logon, startup or a timer.
- Autoruns
- A Sysinternals tool that lists every autostart location on a Windows system in one view.
- Proxy setting
- A configuration that routes web traffic through an intermediate server, which malware may set to intercept traffic.
- netsh winhttp show proxy
- A command that displays the system-wide proxy used by Windows services.
Domain 4: Operational procedures (21%)
Exam tips
- Good ticket notes are specific, factual and complete enough that someone else could continue the work. Severity and priority rise with the number of people affected and the business impact, not with how loudly someone complains.
- An inventory tells you what you own; a CMDB also tells you how items relate and depend on each other. Asset records should include the assigned user, warranty dates and license information, and the asset tag ID is the organization's own identifier, not the serial number.
- Rules for users: AUP. Step-by-step routine task: SOP. Promised response or uptime: SLA. Record of what happened: incident report. Reusable fix: knowledge base article. Access removed at departure: offboarding checklist.
- Test changes in a sandbox and get CAB approval before implementation; every change needs a rollback plan and backups. End-user acceptance comes after implementation, and emergency changes are still documented afterward.
- Incremental: fastest backups, slowest restore (full plus every incremental). Differential: backups grow each day, restore needs only the full plus the latest differential. Untested backups cannot be trusted, and RAID is not a backup.
- Never use water on an electrical fire, never open a power supply, and never wear an ESD strap when working on high-voltage equipment. Lift with your legs, not your back, and touch unpainted metal if no strap is available.
- To learn how to handle or dispose of a chemical, consult its SDS. A UPS keeps power on during outages; a surge suppressor only protects against spikes; a power strip protects against nothing. Local regulations override general disposal advice.
- Order for prohibited content: identify, report through proper channels, preserve evidence and document. PCI DSS covers card data, PHI is health data, GDPR is EU personal data, and PII is any identifying data. Never delete data under legal hold.
- When in doubt on professionalism questions, choose the answer that is calm, respectful, keeps the customer informed and avoids distractions. Never argue, blame the user, post about customers or look through their private data.
- Match extensions to platforms: .bat, .ps1 and .vbs are Windows; .sh is Linux and macOS; .py and .js are cross-platform. The main risks are introducing malware, changing system settings unintentionally and crashes from mishandled resources, so test before deploying.
- SSH (22) replaced Telnet for secure command-line access; RDP (3389) is Windows graphical access and should never be exposed directly to the internet. A VPN secures the connection but is not a remote-control tool by itself, and RMM accounts need MFA.
- Never put confidential or regulated data into a public AI model unless policy explicitly allows it. Always verify AI output, since hallucinations sound confident, and remember that AI features inherit the user's access permissions.
Key terms
- Ticketing system
- Software that records, routes and tracks support requests and incidents from report to resolution.
- Category
- A classification of a ticket by type, such as hardware or network, used for routing and reporting.
- Severity
- A measure of how serious a problem's impact is on users and the business.
- Priority
- The order in which tickets are handled, usually set from impact and urgency.
- Escalation
- Passing a ticket to a higher tier or specialist when it exceeds the current technician's skill, authority or time limit.
- Progress notes
- Time-ordered records of actions, findings and communications on a ticket.
- Resolution
- The closing note stating the cause, the fix applied and the user's confirmation.
- Inventory list
- A record of every asset with details such as ID, model, serial number, location, status and assigned user.
- CMDB (configuration management database)
- A database of configuration items and the relationships and dependencies between them.
- Configuration item (CI)
- Any component tracked in a CMDB, such as a server, application, service or document.
- Asset tag
- A label with a unique organizational ID, often a barcode, QR code or RFID tag, attached to equipment.
- Procurement life cycle
- The stages of an asset from purchase request through deployment, maintenance and disposal.
- Software license compliance
- Ensuring the number and type of installations match what the license agreements allow.
- Assigned user
- The person recorded as responsible for a specific asset.
- Acceptable use policy (AUP)
- A policy stating what users may and may not do with an organization's systems and data.
- Incident report
- A factual record of an incident: what happened, when, what was affected and what actions were taken.
- Standard operating procedure (SOP)
- Step-by-step instructions for performing a routine task consistently.
- Onboarding checklist
- A list of steps for setting up a new user's accounts, access, equipment and training.
- Offboarding checklist
- A list of steps for removing a departing user's access, recovering equipment and handling their data.
- Service level agreement (SLA)
- A formal agreement defining service targets such as response times and availability.
- Knowledge base (KB) article
- A documented solution or how-to guide for technicians or end users.
- Change request
- A form describing a proposed change, its purpose, scope, schedule, owner and risk.
- Scope
- The systems, users, locations and services a change will affect.
- Risk analysis
- An assessment of the likelihood and impact of a change failing, and of not making it.
- Change advisory board (CAB)
- A group of stakeholders that reviews and approves or rejects normal changes.
- Sandbox
- An isolated test environment that mirrors production so changes can be tested safely.
- Rollback plan
- Documented steps to return a system to its previous state if a change fails.
- End-user acceptance
- Confirmation by users or the business owner that the changed system meets their needs.
- Full backup
- A copy of all selected data, simplest to restore but the slowest and largest to create.
- Incremental backup
- A copy of data changed since the last backup of any type; restore needs the full plus every incremental.
- Differential backup
- A copy of data changed since the last full backup; restore needs the full plus the latest differential.
- Synthetic full backup
- A full backup assembled on backup storage from a previous full and later incrementals.
- 3-2-1 rule
- Keep three copies of data on two types of media with one copy off-site.
- Grandfather-father-son (GFS)
- A rotation scheme using daily, weekly and monthly backup sets kept for increasing lengths of time.
- RPO and RTO
- Recovery point objective is the acceptable data loss; recovery time objective is how quickly service must return.
- ESD (electrostatic discharge)
- A sudden flow of static electricity that can damage electronic components without being felt.
- ESD wrist strap
- A strap with a resistor that connects you to ground so static bleeds away safely while working on components.
- ESD mat
- A grounded work surface that keeps components and tools at the same potential.
- Antistatic bag
- Packaging that shields components from static charges during storage and transport.
- Grounding
- Connecting equipment to earth so fault current flows to ground instead of through a person.
- Class C fire
- A fire involving energized electrical equipment, fought with non-conductive agents such as CO2.
- PPE (personal protective equipment)
- Gear such as safety glasses, gloves and masks that protects the wearer from hazards.
- Safety data sheet (SDS)
- A manufacturer's document describing a product's hazards, safe handling, first aid, spill response and disposal.
- E-waste
- Discarded electronic equipment that must be recycled through certified channels because it contains hazardous materials.
- Toner vacuum
- A vacuum with fine filtering designed to safely collect toner particles.
- Surge suppressor
- A device that diverts voltage spikes away from connected equipment, rated in joules.
- UPS (uninterruptible power supply)
- A battery-backed device that keeps equipment powered through outages and sags long enough for a clean shutdown.
- Brownout (sag)
- A temporary drop in voltage below normal levels.
- Hot aisle / cold aisle
- A server room layout where equipment intakes face a cool aisle and exhausts face a hot aisle.
- Chain of custody
- A documented record of everyone who handled evidence, when and what they did, preserving its integrity.
- EULA (end-user license agreement)
- The contract defining the terms under which software may be used.
- DRM (digital rights management)
- Technology that restricts copying and use of digital content to enforce licensing.
- Open-source license
- A license that makes source code available and permits use, modification and sharing under stated conditions.
- PII (personally identifiable information)
- Any data that can identify a specific person.
- PHI (protected health information)
- Health information linked to an individual, protected in the US under HIPAA.
- PCI DSS
- The Payment Card Industry Data Security Standard for protecting payment card data.
- GDPR
- The EU General Data Protection Regulation governing personal data of people in the EU.
- Active listening
- Giving full attention, not interrupting, taking notes and restating the problem to confirm understanding.
- Open-ended question
- A question that invites a detailed answer, used to gather information.
- Closed-ended question
- A question with a short or yes/no answer, used to narrow down a problem.
- Jargon
- Technical terms and acronyms that a non-technical customer may not understand.
- Confidentiality
- Protecting customers' private information and not reading, copying or discussing it.
- Setting expectations
- Telling the customer what will be done, how long it will take and what options and costs exist.
- Follow-up
- Contacting the customer after the work to confirm the problem stays solved.
- Script
- A plain-text file of commands executed in order by an interpreter.
- Batch file (.bat)
- A Windows script run by the Command Prompt interpreter.
- PowerShell (.ps1)
- Microsoft's powerful scripting language and shell for administering Windows and other systems.
- Shell script (.sh)
- A script for Linux or macOS run by bash or another shell.
- Variable
- A named storage location that holds a value a script can use and change.
- Loop
- A structure that repeats a set of commands, for example for each item in a list.
- Execution policy
- A PowerShell setting that controls whether and which scripts are allowed to run.
- RDP (Remote Desktop Protocol)
- Microsoft's protocol for full graphical remote desktop sessions, by default on TCP port 3389.
- SSH (Secure Shell)
- An encrypted remote command-line protocol, by default on TCP port 22, that replaced Telnet.
- VNC (Virtual Network Computing)
- A cross-platform screen-sharing protocol that controls the console session, often needing an encrypted tunnel.
- VPN (virtual private network)
- An encrypted tunnel connecting a remote device to a private network.
- RMM (remote monitoring and management)
- A platform for monitoring, patching, scripting and remotely controlling many endpoints.
- WinRM (Windows Remote Management)
- A service that lets administrators run PowerShell commands on remote Windows computers.
- SPICE
- A remote display protocol used to access virtual machine consoles.
- NLA (Network Level Authentication)
- An RDP setting that requires users to authenticate before a remote session is created.
- Generative AI
- AI that creates new text, images or code based on patterns learned from training data.
- Large language model (LLM)
- An AI model trained on large amounts of text to generate and interpret language.
- Hallucination
- A confident but false or invented output produced by an AI model.
- Bias
- Systematic unfairness in AI output caused by skewed training data or design.
- Appropriate-use policy
- An organizational policy defining approved AI tools, permitted data and review requirements.
- Public model
- A consumer AI service open to anyone whose terms may allow storing or training on user input.
- Private model
- An AI model run by or contracted for an organization that keeps its data under the organization's control.
Study A+ Core 2 for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the A+ Core 2 study planLessons, quizzes, exam simulations and hands-on labs.